VYPR
Medium severity4.9NVD Advisory· Published Mar 18, 2014· Updated May 6, 2026

CVE-2014-2532

CVE-2014-2532

Description

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

Affected products

7
  • OpenBSD/OpenSSH6 versions
    cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*range: <=6.5
    • cpe:2.3:a:openbsd:openssh:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:openbsd:openssh:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openbsd:openssh:6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openbsd:openssh:6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:openbsd:openssh:6.4:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:communications_user_data_repository:10.0.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

23

News mentions

0

No linked articles in our index yet.